RATATOSKRATATOSK
Sign in

Releases

AI-analyzed release notes for CNCF graduated and incubating projects.

Project: KubescapeClear ×
Kubescapev4.0.12SecurityAug 12, 2026

A corrective and performance-focused release with operator-visible default and constraint changes, deprecated flag removal, and dependency vulnerability fixes. It also expands scanning, output, registry, and MCP capabilities.

Action needed (3)

  • securityBatch dependency vulnerability fixes

    Batch 1 and 2 dependency vulnerability fixes are included in this release.

  • breakingRegoV1 evaluation and v0 compatibility shim removal

    Rego evaluation now uses RegoV1 and drops the v0 compatibility shim in this release.

  • breakingLoopback-only constraint

    A loopback-only constraint is applied in this release.

Check if affected (3)

  • breakingOpt-in pprof debug server

    Applies if you enable the pprof debug server.

    The pprof debug server is opt-in in this release.

  • breaking--frameworks default set to all

    Applies if you do not configure --frameworks.

    The default for --frameworks is all when the flag is not configured.

  • breakingDeprecated flags removal

    Applies if you configure deprecated flags.

    Deprecated flags are removed, and the scan documentation is updated in this release.

Source
Kubescapev4.0.11SecurityJul 22, 2026

A feature and maintenance release that adds scanning, reporting, export, MCP, vulnerability-adaptor, and policy capabilities while correcting air-gapped, exception, scan, SARIF, and image-scan behavior. deploy-library now uses the embedded VAP bundle by default.

Check if affected (1)

  • breakingThe deploy-library bundle source

    Applies if you use deploy-library.

    In v4.0.11, deploy-library serves the embedded bundle by default. It downloads a bundle only when --from-release is used.

Source
Kubescapev4.0.10SecurityJun 30, 2026

This release removes an orphan CRD, adds operator-facing capabilities and output changes, and corrects runtime, validation, reporting, and scan-processing defects. No security advisories or explicitly exploitable vulnerabilities are disclosed.

Check if affected (1)

  • breakingSecurityException CRD removal

    Applies if you use the SecurityException CRD.

    The orphan, uninstallable SecurityException CRD and its test are removed in this release.

Source
Kubescapev4.0.9SecurityMay 29, 2026

A broad maintenance release with correctness fixes, new CLI and reporting capabilities, anonymization updates, a performance improvement, added validation, and dependency refreshes. It also includes security fixes alongside changes to output and push defaults.

Action needed (3)

  • securityDependency updates for security advisories

    Dependencies are updated to address security advisories.

  • securityEnvFrom clearing in container data removal

    removeContainersData now clears EnvFrom to prevent secret name leakage.

  • securityEnv[].ValueFrom clearing in container data removal

    removeContainersData and removeEphemeralContainersData now clear Env[].ValueFrom.

Check if affected (3)

  • security/v1/results access control hardening

    Applies if you use /v1/results.

    The /v1/results endpoint is hardened to remediate IDOR.

  • breakingThe pdf/html output default changed to file output

    Applies if you use pdf/html output.

    The default for pdf/html output now writes to a file instead of stdout.

  • breakingThe push default changed to opt-in

    Applies if you use push.

    The default for push is now false, so opting in is required.

Source
Kubescapev4.0.7SecurityMay 8, 2026

A maintenance release with operator-facing correctness fixes, new control and TLS configuration capabilities, narrower CRD scan-mode support, and interface simplifications. It also improves validation and error reporting, with no security advisories or vulnerability disclosures.

Check if affected (3)

  • breakingprotobuf content type removal

    Applies if you use protobuf content type.

    The protobuf content type is removed in v4.0.7.

  • breakingSidecar requirement removal

    Applies if you use a sidecar.

    Services are obtained from the API in v4.0.7, removing the sidecar requirement.

  • breakingThe --output flag, removed

    Applies if you configure --output.

    The --output flag is removed in v4.0.7.

Source
Browse by month